Persian Hack Team

20 exploits Active since Jun 2026
CVE-2017-20280 EXPLOITDB HIGH text WORKING POC
Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attackers can send GET requests to index.php with malicious pid values in the task=project&view=grid endpoint to extract sensitive database information.
CVSS 8.2
CVE-2017-20279 EXPLOITDB HIGH text WORKING POC
Joomla Payage 2.05 SQL Injection via aid Parameter
Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to extract sensitive database information using boolean-based blind or time-based blind techniques.
CVSS 8.2
CVE-2016-20074 EXPLOITDB MEDIUM text WORKING POC
WordPress Lazy Content Slider Plugin 3.4 CSRF
WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify plugin configuration parameters like lzcs_color and lzcs_count.
CVSS 4.3
EIP-2026-113997 EXPLOITDB text WORKING POC
WordPress Plugin RB Agency 2.4.7 - Local File Disclosure
EIP-2026-109760 EXPLOITDB text WRITEUP
MyCustomers CMS 1.3.873 - SQL Injection
EIP-2026-108816 EXPLOITDB text WORKING POC
Joomla! Component onisPetitions 2.5 - 'tag' SQL Injection
EIP-2026-108765 EXPLOITDB text WRITEUP
Joomla! Component JTAG Calendar 6.2.4 - 'search' SQL Injection
EIP-2026-108815 EXPLOITDB text WORKING POC
Joomla! Component onisMusic 2 - 'tag' SQL Injection
EIP-2026-108817 EXPLOITDB text WORKING POC
Joomla! Component onisQuotes 2.5 - 'tag' SQL Injection
EIP-2026-108859 EXPLOITDB text WORKING POC
Joomla! Component Soccer Bet 4.1.5 - 'cat' SQL Injection
EIP-2026-108874 EXPLOITDB text WORKING POC
Joomla! Component Sponsor Wall 7.0 - 'wallid' SQL Injection
EIP-2026-108890 EXPLOITDB text WORKING POC
Joomla! Component Vik Booking 1.7 - SQL Injection
EIP-2026-108474 EXPLOITDB text WORKING POC
Joomla! Component com_payplans 3.3.6 - SQL Injection
EIP-2026-108290 EXPLOITDB text WORKING POC
Joomla! Component com_bt_media 1.0 - SQL Injection
EIP-2026-108631 EXPLOITDB text WRITEUP
Joomla! Component Easy Youtube Gallery 1.0.2 - SQL Injection
EIP-2026-108640 EXPLOITDB text WORKING POC
Joomla! Component Event Booking 2.10.1 - SQL Injection
EIP-2026-101525 EXPLOITDB text WORKING POC
ARG-W4 ADSL Router - Multiple Vulnerabilities
EIP-2026-101099 EXPLOITDB python WORKING POC
TP-LINK TD-W8951ND - Denial of Service
EIP-2026-101098 EXPLOITDB text WORKING POC
TP-LINK TD-W8151N - Denial of Service
EIP-2026-101446 EXPLOITDB text WORKING POC
Shuttle Tech ADSL Wireless 920 WM - Multiple Vulnerabilities